Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 236

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
OPEC+ debates making oil output hike amid Iran war paralysis, sources say
Older Americans face big tax changes. Here's where they can find free filing help
The PWHL is growing and post-Olympics boom may take women's hockey to the next level
We're trimming our stake in an AI winner to take advantage of great prices
Levi Strauss revenue jumps again, with DTC making up more than half of sales for the first time
Trump praises Hungary PM Viktor Orbán after Vance calls him at Budapest rally
AWS teams working around the clock to keep Middle East services up after drone strikes, CEO says
Movie: Half Lives
Movie: Manson Family Vacation
Movie: The Children's Train